CVSS 3 Base Score:

Posted On:

Assessed Risk Level:
High

In July 2018, the ActiveMQ project released fixes for several vulnerabilities announced in June 2018. Puppet Enterprise 2018.1.5 and 2019.0.1 ship with an updated version of ActiveMQ that has addressed these vulnerabilities.

For more information about these vulnerabilities refer to the ActiveMQ release notes(https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12343307)

Status:

Affected software versions:
  • Puppet Enterprise versions prior to 2019.0.1
  • Puppet Enterprise versions prior to 2018.1.5
Resolved in:
  • Puppet Enterprise 2019.0.1
  • Puppet Enterprise 2018.1.5